Pradeep Agrawal created RANGER-4163:
---------------------------------------

             Summary: Upgrade spring framework to 5.3.26
                 Key: RANGER-4163
                 URL: https://issues.apache.org/jira/browse/RANGER-4163
             Project: Ranger
          Issue Type: Bug
          Components: admin
    Affects Versions: 2.2.0
            Reporter: Pradeep Agrawal
             Fix For: 3.0.0


[https://nvd.nist.gov/vuln/detail/CVE-2022-22970]

[https://nvd.nist.gov/vuln/detail/CVE-2022-22971] 

[https://github.com/spring-projects/spring-framework/releases/tag/v5.3.20] 

Spring seems to be vulnerable to DoS attacks when handling file uploads.

We´ve got some Security Reports and need a fix in future releases.

Upgrading to 5.3.20 should be enough.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to